Intel

AIKIDO-2024-10476

nifi-framework-core is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log FileCVE-2024-52067 Published Nov 25, 2024

69

Medium Risk

This Affects:

javanifi-framework-core
1.16.0 - 1.28.0
Fixed in 1.28.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to potential exposure of sensitive information. During flow synchronization, optional debug logging of parameter context values may occur if an authorized administrator enables debug logging for framework flow synchronization. This could cause the application to log parameter names and values, which might include sensitive information depending on the flow configuration.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges

Background info

nifi-framework-core is vulnerable to Insertion of Sensitive Information into Log File in versions 1.16.0 - 1.28.0.

How to fix this

Upgrade the org.apache.nifi:nifi-framework-core library to the patch version.